mirror of
https://github.com/boku7/Loki
synced 2026-06-06 15:24:27 +00:00
Update README.md
This commit is contained in:
@@ -2,8 +2,8 @@
|
||||
Loki is a stage-1 command and control (C2) framework written in Node.js, built to script-jack vulnerable Electron apps _[MITRE ATT&CK T1218.015](https://attack.mitre.org/techniques/T1218/015/)_. Developed for red team operations, Loki enables evasion of security software and bypasses application controls by exploiting trusted, signed Electron apps.
|
||||
|
||||
Script-jacking is the act of hijacking the execution flow of an Electron app by modifying JavaScript files loaded at runtime with arbitrary Node.js code. This technique can be leveraged to:
|
||||
- Backdoor the Electron app
|
||||
- Hollow out the Electron app
|
||||
- __Backdoor the Electron app__
|
||||
- __Hollow out the Electron app__
|
||||
- Chain execution to another process
|
||||
|
||||
While several tools already address leveraging script-jacking to chain execution to another process, Loki is the first to enable backdooring and hollowing of signed Electron apps without invalidating their code signing signature.
|
||||
|
||||
Reference in New Issue
Block a user